Impact
The vulnerability exists in the Siebel Management Console component of Oracle Siebel CRM Deployment and is an improper access control flaw (CWE-284). A high‑privileged attacker who has network access through HTTP can exploit the flaw to take full control of the deployed system, compromising confidentiality, integrity, and availability. Successful exploitation leads to a complete system takeover, with the potential to affect other integrated products within the deployment due to the scope change indicated by the vulnerability.
Affected Systems
Oracle Corporation’s Siebel CRM Deployment is affected in all versions from 17.0 through 26.7. The vulnerability resides in the Management Console and is applicable only to deployments of the Siebel CRM product that use these version ranges.
Risk and Exploitability
The CVSS v3.1 base score of 9.1 indicates critical severity. With an EPSS score of less than 1%, exploitation is considered unlikely but still possible, particularly to highly privileged attackers. The vulnerability is not listed in the CISA KEV catalog. An attacker can target the exposed HTTP interface of the Siebel Management Console, gaining privileged access and potentially impacting additional products that are part of the same deployment environment.
OpenCVE Enrichment